$ whoami
Tsaqif Fawwaz - Ethical Hacker & Security Researcher
$ echo $passion
Cybersecurity | Penetration Testing | Vulnerability Research
Cybersecurity Enthusiast | Ethical Hacker | CTF Player
Passionate about uncovering vulnerabilities, securing systems, and sharing knowledge through write-ups and research.
I'm Muhammad Tsaqif Fawwaz Nasywan, a passionate cybersecurity enthusiast and ethical hacker pursuing a degree in Applied Informatics at Politeknik Elektronika Negeri Surabaya.
My journey in cybersecurity is driven by an insatiable curiosity about system vulnerabilities and security mechanisms. I dedicate my time to studying penetration testing techniques, reverse engineering, network security, and cryptography to build a strong foundation in offensive and defensive security.
I actively participate in Capture The Flag (CTF) competitions and security challenges, continuously expanding my skill set. I document my learning journey through detailed write-ups and technical blogs, sharing insights and methodologies with the cybersecurity community.
My goal is to become a proficient security professional capable of identifying and mitigating sophisticated threats while contributing to a safer digital ecosystem.
Download CVWeb App Testing, Network Pentesting, Vulnerability Assessment, Burp Suite, Metasploit
TCP/IP, Packet Analysis, Wireshark, Sniffing, Man-in-the-Middle Attacks
Encryption, Hashing, Digital Signatures, Steganography, Cipher Analysis
Reverse Engineering, Binary Analysis, Dynamic/Static Analysis, IDA Pro
Python, Bash, JavaScript, PHP, C - Exploit Development & Scripting
Capture The Flag, Web Exploitation, Reverse Engineering, Steganography, Forensics
Complete write-up on identifying and exploiting SQL injection vulnerabilities in web applications. Includes bypass techniques, authentication evasion, and data exfiltration methods.
Read Write-upComprehensive guide to MITM attacks using ARP spoofing. Covers network sniffing, session hijacking, and credential harvesting in a controlled environment.
Read Write-upDetailed walkthrough of challenging CTF scenarios including privilege escalation, hash cracking, and forensic analysis. Tools: Hashcat, John, Ghidra, Volatility.
Read Write-upAnalysis of a trojan sample using IDA Pro and dynamic debugging. Covers unpacking, function identification, API hooking, and behavioral analysis.
Read Write-upFinding and exploiting Cross-Site Scripting vulnerabilities. Covers reflected XSS, stored XSS, DOM-based XSS, and WAF bypasses using Burp Suite.
Read Write-upSolutions to cryptographic puzzles including RSA attacks, weak cipher analysis, and side-channel attacks. Python scripts included.
Read Write-upIn Progress
Comprehensive security fundamentals and best practices
Active Member
50+ Machines Rooted | Ranked Top 5%
2500+ Points
Completed 100+ Security Training Rooms
Active Participant
Multiple competition victories
Surabaya, Indonesia
tsaqif.fawwaz@example.com
+62 812 3456 7890
Always Available for Security Discussions